Skip to content
Content type · 473 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 473 sort newestlargest fineoldest
€10,000 Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania €10,000 on 2026-01-29 for: Insufficient legal basis for… Italy ·Garante ·Art. 5, 6, 9 Education Processing Public Authority Jan 29, 2026
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Direct Marketing Telecommunications Consent Jan 15, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Healthcare Personal Data Jan 12, 2026
€27M FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Data Breaches Access Controls NL Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Access Controls Security Jan 8, 2026
€15M ONVOLDRAAGLIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. De Franse autoriteit voor gegevensbescherming (CNIL) heeft FREE een boete van 15.000.000 euro opgelegd. Het bedrijf heeft een datalek geleden als gevolg van onvoldoende technische… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Notification Obligation NL Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Data Breaches Access Controls Security Jan 8, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Telecommunications Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Telecommunications Controllers Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Controllers Direct Marketing IP Address Dec 31, 2025
€5,000 Vodafone España, S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 5.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Accuracy Processing IP Address NL Dec 30, 2025
€27,000 Vodafone España, S.A.U.: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van 27.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Telecommunications NL Dec 30, 2025
€27,000 Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Although the complainant (a former Vodafone customer) had requested Vodafone to delete his data in 2015 and this request had been confirmed by the company, he received more than… SPAIN ·aepd ·Art. 5 Personal Data Telecommunications Supervisory Authorities Dec 30, 2025
€5,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone… SPAIN ·aepd ·Art. 5 Accuracy Telecommunications Personal Data Dec 30, 2025
€40,000 Slovak Telekom: Insufficient technical and organisational measures to ensure information security The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Controllers Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·azop ·Art. 5, 6 Personal Data Accuracy Telecommunications Dec 30, 2025
€20,000 Telecommunicatiebedrijf: Onvoldoende juridische basis voor gegevensverwerking. De Kroatische gegevensbeschermingsautoriteit (DPA) heeft een telecombedrijf een boete van 20.000 euro opgelegd. Een betrokkene had een klacht ingediend bij de DPA, waarin hij… CROATIA ·azop ·Art. 5, 6 Accuracy Processing Personal Data NL Dec 30, 2025
€40,000 Slovak Telekom: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Personal Data NL Dec 30, 2025
€15,000 Crowd Entertainment Limited: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Een boete van €15.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Right of Access Data Controller NL Dec 10, 2025
€15,000 Crowd Entertainment Limited: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Crowd Entertainment Limited. The controller failed to adequatly react to a data subjects request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Dec 10, 2025
€72,000 TIGER MEDIA INC.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined TIGER MEDIA INC. €72,000 on 2025-12-03 for: Insufficient legal basis for data processing. Spain ·aepd ·Art. 6, 27 Telecommunications Processing Supervisory Authorities Dec 3, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Processors Processing Data Processor NL Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Processing Agreement Employees Processors Nov 24, 2025
€750,000 LES PUBLICATIONS CONDE NAST: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 750,000 on LES PUBLICATIONS CONDE NAST. The controller used multiple cookies on its website but failed to adequately implement them. FRANCE ·CNIL ·Art. 82 Cookies IP Address Controllers Nov 20, 2025
€750,000 LES PUBLICATIES CONDE NAST: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 750.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Cookies Data Controller Controllers NL Nov 20, 2025
€72,000 AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Cookies Direct Marketing Nov 14, 2025
€40,000 Quarantadue S.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 40.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Processing Controllers Data Controller NL Nov 13, 2025
€40,000 Quarantadue S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Quarantadue S.r.l. The controller produced a television series about a criminal case which included real audio recordings that… ITALY ·Garante ·Art. 5 IP Address Controllers Processing Nov 13, 2025
€20,000 Multimedia News Società Cooperativa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12 Personal Data Data Controller Controllers NL Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Multimedia News Società Cooperativa. The controller failed to adequatly react to a request by a data subject to exercise their… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€150,000 DIGI SPAIN TELECOM, S.L.U.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 150.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). aepd ·Art. 6 ·Insufficient legal basis for data processing Data Controller Processing Personal Data NL Sep 17, 2025
€150,000 DIGI SPAIN TELECOM, S.L.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 150,000 on Digi Spain Telecom S.L.U. The controller rejected the application for a contract due to outstanding debt, despite this being… aepd ·Art. 6 ·Insufficient legal basis for data processing Controllers Telecommunications Processing Agreement Sep 17, 2025
€200M GOOGLE LLC: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 200,000,000 on GOOGLE LLC. While creating an account for the controller's services, the controller designed the cookie consent process in… FRANCE ·CNIL ·Art. 82 Direct Marketing Cookies Marketing Sep 1, 2025
€200M GOOGLE LLC: Onvoldoende juridische basis voor de verwerking van gegevens. 200 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Marketing Cookies Direct Marketing NL Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 125,000,000 on GOOGLE IRELAND LIMITED. While creating an account for the controller's services, the controller designed the cookie consent… FRANCE ·CNIL ·Art. 82 Direct Marketing Cookies Marketing Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Onvoldoende juridische basis voor de verwerking van gegevens. 125.000.000 euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Marketing Direct Marketing Consent NL Sep 1, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 18,000 on the GRUPO BONATEL SL. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·aepd ·Art. 5 Security Telecommunications Controllers Aug 22, 2025
€18,000 GRUPO BONATEL SL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Controllers NL Aug 22, 2025
€6,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 6,200 on a media company. The controller failed to comply with an order from the DPA to implement an adequate cookie banner. AUSTRIA ·dsb ·Art. 58 Supervisory Authorities Supervision Cookies Aug 6, 2025
€6,200 Mediabedrijf: Onvoldoende samenwerking met de toezichthoudende instantie. Boete van 6.200 euro - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·dsb ·Art. 58 Telecommunications Supervisory Authorities Supervision NL Aug 6, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Health Data IP Address Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Data Controller NL Aug 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Controllers Personal Data Telecommunications Jul 4, 2025
€3,000 Zougla TZI-AP, een anoniem massamediaconcern: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Personal Data Processing Data Controller NL Jul 4, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Data Processor Telecommunications NL Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Personal Data NL Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Telecommunications Controllers Security Jun 25, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025